#Denial of Service
All CosmicBytez Labs articles tagged #Denial of Service, across news, security advisories, how-to guides, and projects.
- News
One Packet, No Password: High-Severity TDengine Zero-Day Threatens Industrial Servers
A high-severity zero-day, CVE-2026-42542, crashes TDengine time-series database servers with one packet — 730,000+ instances run in OT, IoT, and energy.
- Security
Unauthenticated Denial-of-Service in Apache Qpid Broker-J ≤ 10.1.0
A pre-auth denial-of-service flaw (CVSS 7.5) in Apache Qpid Broker-J lets attackers crash the AMQP broker via malformed frame headers.
- News
New Windows Defender Zero-Day Blocks Microsoft Antivirus Updates
Researcher Abdelhamid Naceri released BigDiskBuster, a zero-day that freezes Windows Defender signature and platform updates indefinitely.
- Security
CVE-2026-94083 & CVE-2026-94084: Suricata DoH2/HTTP2 Flaws Let Attackers Crash IDS/IPS
Suricata 8.0.7 fixes two CVSS 9.4 unauthenticated crash bugs in its DoH2 and HTTP/2 parsers that can blind network monitoring. Upgrade now.
- News
ISC Patches 14 Vulnerabilities in BIND 9 DNS Server Software
ISC fixes 14 BIND 9 flaws, including 7 high-severity bugs that can crash named, exhaust memory, or poison DNS caches. No active exploitation reported.
- Security
CVE-2026-13260: IBM Verify Identity Access Remote Denial-of-Service Flaw
IBM Verify Identity Access lets a remote, unauthenticated attacker exhaust resources and cause denial of service via unvalidated requests.
- Security
CVE-2026-59682: OpenRGB Arbitrary File Overwrite via SAVE_PROFILE
OpenRGB's network protocol lets remote attackers overwrite (and delete) arbitrary files through the SAVE_PROFILE message, up to v1.0rc3.
- News
Cisco Warns of ASA and FTD VPN Flaw Actively Exploited to Crash Firewalls
CVE-2026-20349 (CVSS 8.6) in Cisco ASA and FTD allows unauthenticated remote attackers to crash SSL VPN devices via crafted HTTP requests — no workaround...
- Security
CVE-2026-20349: Cisco ASA and FTD Heap Inspection Vulnerability
Cisco Secure Firewall ASA and FTD contain a heap inspection vulnerability allowing unauthenticated remote attackers to crash devices and trigger a denial...
- Security
CVE-2026-35547: FreeBSD libnv Heap Buffer Overflow Allows
A critical heap buffer overflow in FreeBSD's libnv library allows an unprivileged program to write outside heap allocation bounds during message header...
- Security
CVE-2026-26477: DokuWiki media_upload_xhr() Denial of Service
A high-severity denial-of-service vulnerability in DokuWiki v.2025-05-14b 'Librarian' allows remote attackers to crash the application by exploiting the...
- Security
CVE-2018-25169: Denial of Service Vulnerability Catalogued
A denial of service vulnerability in AMPPS 2.7, a local web server stack for developers, has been formally assigned CVE-2018-25169 with a CVSS score of...